stack/secrets/.env.example
tim 0108868a2c Document all post-secret-change update procedures
Add a single quickstart table covering Cloudflare DDNS, Usenet, NZBgeek,
WireGuard, stack .env, and bootstrap; point secrets/.env.example and
AGENTS.md at the same workflow.
2026-07-22 19:48:56 -07:00

47 lines
1.5 KiB
Text

# Copy to secrets/.env and fill in. NEVER commit secrets/.env
#
# After editing secrets on the server:
# Usenet: ./scripts/configure-usenet.sh
# Cloudflare: ./scripts/render-cloudflare-ddns-env.sh
# docker compose up -d cloudflare-ddns --force-recreate
# Full table: see quickstart.md → "After changing secrets"
#
# scripts/configure-usenet.sh accepts these names (and a few aliases).
# --- NZBgeek (Prowlarr indexer) ---
NZBGEEKUSERNAME=
NZBGEEKEMAIL=
NZBGEEKAPI=https://api.nzbgeek.info/
# API key (also accepted as NZBGEEK_API_KEY)
NZBKEEPKEY=
# --- Newshosting (Usenet / SABnzbd) ---
# NEWSHOSTINGAPI is the NNTP host hostname
NEWSHOSTINGAPI=news.newshosting.com
NEWSHOSTINGSSLPORT=563
NEWSHOSTINGUSER=
# also accepted: NEWSHOSTING_PASS, NEWSHOSTINGPASS
HNEWSHOSTINGPASS=
NEWSHOSTINGCONNECTIONS=20
# --- Tweaknews (Usenet / SABnzbd) ---
# TWEAKNEWSAPI is the NNTP host (e.g. news.tweaknews.eu or newshosting.tweaknews.eu)
TWEAKNEWSAPI=news.tweaknews.eu
TWEAKNEWSSSLPORT=563
TWEAKNEWSLOGIN=
TWEAKNEWSPASSWORD=
TWEAKNEWSCONNECTIONS=40
# --- Cloudflare DDNS (timothyjmiller/cloudflare-ddns) ---
# API token needs Zone.DNS Edit on the zone (not the global API key)
CLOUDFLAREAPIKEY=
# optional aliases
CLOUDFLARE_API_TOKEN=
CLOUDFLAREZONEID=
CLOUDFLAREACCOUNTID=
CLOUDFLAREDOMAIN=devopshomelab.com
# Comma-separated labels (or FQDNs). Apex is always included.
CLOUDFLARESUBDOMAINS=mc,minecraft,vpn,www,forgejo,jellyfin
# false = DNS-only (needed for VPN); true = orange-cloud proxy
CLOUDFLARE_PROXIED=false
CLOUDFLARE_UPDATE_CRON=@every 5m